This article was AI-generated as part of an experimental historical-content project. The date reflects the period being analyzed rather than the date the article was originally written.
Most digital identity work rests on one question: is this really them? A fake profile, a spoofed domain, a lookalike email address, a synthetic image. The job is to show that whatever is pretending to be a person or a company is not, and then get it taken down.
OpenAI’s launch today breaks that frame quietly. The actor can now be genuine and the action still unintended.
What OpenAI released
ChatGPT agent combines Operator’s ability to click and type on websites with deep research’s ability to synthesize, inside ChatGPT. It runs on its own virtual computer with a visual browser, a text browser, a terminal and connectors to apps such as Gmail and GitHub. The feature that matters for identity is takeover mode. A user can log in to any website through the agent’s browser, and the agent can then work inside that session. Pro users get it today, Plus and Team over the next few days, Enterprise and Education in the coming weeks. Access in the EEA and Switzerland is still pending, and the Operator preview will be sunset in a few weeks.
OpenAI is unusually direct about risk. It calls this the first time users can ask ChatGPT to take actions on the web and says the agent’s overall risk profile is higher. It describes prompt injection, a hidden instruction on a webpage, as a way to trick the agent into “taking a harmful action on a site the user has logged into.” Its stated mitigations are confirmation before consequential actions, an active supervision mode for tasks like sending email, and refusal of high-risk tasks such as bank transfers. Those are the vendor’s descriptions of its own safeguards. How they hold up will be learned in use.
The strategic problem
Consider what a logged-in agent can produce: an email from a real account, a booking under a real name, a comment posted from a verified profile, a form submitted on a supplier portal, a meeting invitation sent to a journalist. Every one of those passes the authenticity test. The account is real. The session was authorized. If something went wrong, it went wrong as you.
That is a different problem from impersonation, and existing playbooks handle it poorly. A platform’s fake-account process does not apply, because the account is not fake. “This was not me” is not quite true either. The accurate statement, “this was my agent, following an instruction I gave or one it picked up from a page,” has no standard form yet.
For executives the exposure is concentrated. Senior people are likely to be early delegators of inbox triage, travel and research, and their accounts carry weight. A wrong reply from a chief executive’s address is the chief executive’s statement until someone explains otherwise.
Reasoning toward a correction path
I would break it into three parts.
Attribution. Can you show what happened? The agent narrates its actions on screen, and the conversation remains. That is a record, and when something goes wrong it should be preserved the way a security team preserves logs.
Disclosure. Who needs to hear “this was an automated action, since reversed,” and in what words? Writing that language before it is needed costs very little.
Scope. OpenAI itself suggests disabling connectors that a task does not need. For people whose accounts speak for an organization, a written rule about which accounts an agent may enter is a reputation control as much as a security one.
In 2023 Bard added a button that admitted answers still need corroboration. Actions need something similar: a way to check, and explain, before the record hardens.
Identity teams have spent years proving that the fake was not the real person. The next set of cases will ask them to explain, publicly and quickly, why the real person did something they never meant to do.